Ansible role for preparing a host for Docker Containers
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Docker
Install and configure the Docker container runtime. On Debian the role installs Docker CE from the official Docker apt repository, on Alpine it installs the distribution packages.
Requirements
| Operating System | Notes |
|---|---|
| Debian | Docker CE from download.docker.com (deb822 repository, amd64 or arm64) |
| Alpine | docker, docker-compose and py3-docker-py from apk |
The role has no role dependencies (meta/main.yaml).
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
type |
No | "" |
Object type. Defined in the defaults, but currently not referenced by any task (see below). |
The AppArmor removal is not controlled by type: it runs whenever the host reports
ansible_facts["virtualization_type"] == "lxc".
Example
type: "server"
What the role does
- On LXC guests, purge the
apparmorpackage (Debian only) and reboot the guest through thereboot containerhandler. Handlers are flushed before Docker is installed. - Alpine: install
docker,docker-composeandpy3-docker-py, then start and enable thedockerservice. - Debian:
- purge the old
containerd,docker-compose,docker-doc,docker.io,podman-dockerandruncpackages; - download the Docker GPG key to
/etc/apt/keyrings/docker.asc; - remove the legacy
/etc/apt/sources.list.d/docker.list(marked in the code for removal after 2026-10-20); - add the
dockerdeb822 repository (stablecomponent); - install
containerd.io,docker-ce,docker-ce-cli,docker-compose-plugin,python3-pip,python3-dockerandnfs-common.
- purge the old
Usage
Run playbook.yaml through Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml
on the controller (works around a Semaphore bug) and then includes the docker role on all hosts with become.
The role is also used as a dependency by other playbooks (for example forgejo and grafana).